Showing posts with label HR 5639. Show all posts
Showing posts with label HR 5639. Show all posts

Tuesday, July 12, 2016

House Passes HR 5639, NIST Improvement

Yesterday as expected the House passed HR 5639, the National Institute of Standards and Technology Improvement Act of 2016 by a voice vote. There was only eleven minutes ‘debate’ on the bill before the vote was taken, but there were no words spoken in opposition to the bill.

As I mentioned in my earlier post there is only one cybersecurity provision in the bill, but it is more of a face-saving slap at the NSA than an effective legislative provision.


The bill, if it reaches the floor of the Senate before the end of the session, will almost certainly be considered under their unanimous consent provisions where it will be passed with no debate and no vote.

Monday, July 11, 2016

Committee Hearings – Week of 7-10-16

Both the House and Senate are in Washington this week, but it is scheduled to be their last week until early September. The hearing schedule is fairly light this week with only three hearings of interest to readers of this blog; two cybersecurity and one PHMSA oversight hearing.

Cybersecurity


On Wednesday the Cybersecurity, Infrastructure Protection, and Security Technologies Subcommittee of the House Homeland Security Committee will be holding a hearing on “Value of DHS’ Vulnerability Assessments in Protecting Our Nation’s Critical Infrastructure”. This will deal with cybersecurity assessments conducted by the DHS Office of Cybersecurity and Communications (CS&C) and Office of Infrastructure Protection (presumably including assessments conducted by ICS-CERT). The witness list includes:

• Matthew J. Eggers, US Chamber of Commerce;
• Robert H. Mayer, United States Telecom Association;
• Mark Clancy, Soltra;
• Mordecai Rosen, CA Technologies; and
• Ola Sage, e-Management

On Tuesday the Energy Subcommittee of the Senate Energy and Natural Resources Committee will be holding a hearing on S 3018. The witness list includes:

• Patricia Hoffman, US Department of Energy;
• Duane D. Highley, Arkansas Electric Cooperative Corporation;
• Rob Manning, Electric Power Research Institute; and
• Brent Stacey, Idaho National Laboratory

Readers will recall that this is the bill that I called for support via a letter writing campaign.

PHMSA


On Tuesday the Surface Transportation and Merchant Marine Infrastructure, Safety, and Security Subcommittee of the Senate Commerce, Science and Transportation Committee will be holding a hearing looking at “The FAST Act, the Economy, and Our Nation’s Transportation System”. It is not clear what portions of the FAST Act will actually be covered in this hearing. The witness list includes:

• Patrick J. Ottensmeyer, Kansas City Southern Railway Company;
• Jay Thompson, Commercial Vehicle Safety Alliance
• David Eggermann, BASF
• Stephen J. Gardner, Amtrak 

On the Floor

There will be a large number of bills considered in the House this week under suspension of the rules with limited debate, no amendments, and requiring a super majority to pass the bill. Of those being considered only one is of specific (if very minor) interest to readers of this blog; HR 5639, the National Institute of Standards and Technology Improvement Act.


The Senate will take another try at starting debate on HR 5293, the FY 2017 DOD spending bill. Amendments (including one to substitute language from S 3000) will not be filed until the first cloture vote is agreed to. I’m not holding my breath, but this could possibly pass and go to conference before the summer recess.

HR 5639 Introduced – NIST Update

Last week Rep. Moolenaar (R,MI) introduced HR 5639, the National Institute of Standards and Technology Improvement Act of 2016. The bill updates the National Institute of Standards and Technology Act (15 USC 272). There is only one minor cybersecurity provision in the bill.

Cybersecurity Provision


Section 11 of the bill makes one small change to 15 USC 278g–3, the computer standards program. It removes the words ‘National Security Agency’ from paragraph (c)(1). That paragraph lists the agencies that NIST must consult with in establishing standards for information systems and cybersecurity standards for federal information systems.

Moving Forward


Moolenaar is a member of the House Science, Space and Technology Committee, the committee to which the bill was assigned for consideration. More importantly many of the ten cosponsors are influential members of the Committee and the Congressional leadership. This is clearly reflected by the fact that the bill will be considered this week under suspension of the rules. The bill will almost certainly pass with substantial bipartisan support.

Commentary



This change was almost certainly included in response to news that the NSA influenced NIST to include backdoors into encryption standards. The change does not prevent NIST from consulting with NSA, or limit what influence NSA has on NIST operations. The change is simply a face saving move by Congress so that it appears that Congress has limited the influence of NSA.

Thursday, July 7, 2016

Bills Introduced – 07-06-16

With both the House and Senate in session yesterday there were 38 bills introduced. Of those three may be of specific interest to readers of this blog:

HR 5634 Making appropriations for the Department of Homeland Security for the fiscal year ending September 30, 2017, and for other purposes. Rep. Carter, John R. [R-TX-31]

HR 5639 To update the National Institute of Standards and Technology Act, and for other purposes. Rep. Moolenaar, John R. [R-MI-4]

HR 5643 To amend the Homeland Security Act of 2002 to provide for active shooter and mass casualty incident response assistance, and for other purposes. Rep. Duckworth, Tammy [D-IL-8] 

The DHS spending bill is being introduced awfully late in the session, particularly for an election year. It is unlikely to receive consideration as a stand-alone bill. Still it will be interesting to see what is included in the Committee Report on this bill.

The NIST authorization bill will be covered only if it includes specific provisions related to cybersecurity, particularly control system security.


The active shooter bill will probably not be mentioned again, but I am hoping that it will have at least some sort of provision requiring the Department to address the unique aspects of active shooter situations at chemical storage/production facilities.
 
/* Use this with templates/template-twocol.html */